All tips
SPF 2 min read

-all or ~all: choosing your SPF policy

Hardfail rejects unlisted senders outright; softfail marks them and delivers anyway. Which you want depends on how complete your record already is.

The final mechanism in an SPF record decides what happens to everything the record did not explicitly authorise. There are four possible qualifiers and only two sensible choices.

The options

  • -all (fail) means unlisted senders are not authorised. The strongest statement, and the one DMARC enforcement effectively expects.
  • ~all (softfail) marks unlisted senders as suspicious but should still be accepted. Intended as a transition state.
  • ?all (neutral) makes no assertion at all. Equivalent to publishing nothing, so do not use it.
  • +all (pass) authorises the entire internet to send as you. Never correct.

How to choose

Publish ~all while you are still discovering who sends mail as your domain, then move to -all once DMARC aggregate reports show a stable, complete picture for several weeks. The move is a one-character edit, and it is the point at which SPF starts doing real work.

Under DMARC it is the alignment that carries the weight, not the qualifier: a DMARC policy of reject will act on an unaligned message whether your record ends in ~all or -all. The qualifier still matters for receivers checking SPF on its own.

The common trap

Teams often leave ~all in place for years because someone once got a bounce after tightening it. The right response is to find the sender that was missing from the record, not to weaken the policy permanently. DMARC reports tell you exactly which IPs are failing and how much mail they send.

Check your SPF record and lookup count
spfpolicyrollout